cbcvebase.

Canonical Ubuntu Linux vulnerabilities

4,117 known vulnerabilities affecting canonical/ubuntu_linux.

Total CVEs
4,117
CISA KEV
46
actively exploited
Public exploits
275
Exploited in wild
85
Severity breakdown
CRITICAL546HIGH1402MEDIUM1947LOW222

Vulnerabilities

Page 129 of 206
CVE-2013-7423P4MEDIUMCVSS 5.0v10.04v12.04+2 more2015-02-24
CVE-2013-7423 [MEDIUM] CWE-17 CVE-2013-7423: The send_dg function in resolv/res_send.c in GNU C Library (aka glibc or libc6) before 2.20 does not The send_dg function in resolv/res_send.c in GNU C Library (aka glibc or libc6) before 2.20 does not properly reuse file descriptors, which allows remote attackers to send DNS queries to unintended locations via a large number of requests that trigger a call to the getaddrinfo function.
nvd
CVE-2017-14341P4MEDIUMCVSS 6.5v14.04v16.04+2 more2017-09-12
CVE-2017-14341 [MEDIUM] CWE-400 CVE-2017-14341: ImageMagick 7.0.6-6 has a large loop vulnerability in ReadWPGImage in coders/wpg.c, causing CPU exha ImageMagick 7.0.6-6 has a large loop vulnerability in ReadWPGImage in coders/wpg.c, causing CPU exhaustion via a crafted wpg image file.
nvd
CVE-2019-12221P4MEDIUMCVSS 6.5v16.04v18.042019-05-20
CVE-2019-12221 [MEDIUM] CWE-787 CVE-2019-12221: An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunctio An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image.a in SDL2_image 2.0.4. There is a SEGV in the SDL function SDL_free_REAL at stdlib/SDL_malloc.c.
nvd
CVE-2017-14173P4MEDIUMCVSS 6.5v14.04v16.04+2 more2017-09-07
CVE-2017-14173 [MEDIUM] CWE-190 CVE-2017-14173: In the function ReadTXTImage() in coders/txt.c in ImageMagick 7.0.6-10, an integer overflow might oc In the function ReadTXTImage() in coders/txt.c in ImageMagick 7.0.6-10, an integer overflow might occur for the addition operation "GetQuantumRange(depth)+1" when "depth" is large, producing a smaller value than expected. As a result, an infinite loop would occur for a crafted TXT file that claims a very large "max_value" value.
nvd
CVE-2017-14633P4MEDIUMCVSS 6.5v14.04v16.04+1 more2017-09-21
CVE-2017-14633 [MEDIUM] CWE-125 CVE-2017-14633: In Xiph.Org libvorbis 1.3.5, an out-of-bounds array read vulnerability exists in the function mappin In Xiph.Org libvorbis 1.3.5, an out-of-bounds array read vulnerability exists in the function mapping0_forward() in mapping0.c, which may lead to DoS when operating on a crafted audio file with vorbis_analysis().
nvd
CVE-2019-3459P4MEDIUMCVSS 6.5v14.04v16.04+2 more2019-04-11
CVE-2019-3459 [MEDIUM] CWE-125 CVE-2019-3459: A heap address information leak while using L2CAP_GET_CONF_OPT was discovered in the Linux kernel be A heap address information leak while using L2CAP_GET_CONF_OPT was discovered in the Linux kernel before 5.1-rc1.
nvd
CVE-2014-5461P4MEDIUMCVSS 5.0v12.04v14.042014-09-04
CVE-2014-5461 [MEDIUM] CWE-119 CVE-2014-5461: Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5.2.x before 5.2.3 allows contex Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5.2.x before 5.2.3 allows context-dependent attackers to cause a denial of service (crash) via a small number of arguments to a function with a large number of fixed arguments.
nvd
CVE-2018-5812P4MEDIUMCVSS 6.5v14.04v16.04+1 more2018-12-07
CVE-2018-5812 [MEDIUM] CWE-476 CVE-2018-5812: An error within the "nikon_coolscan_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versi An error within the "nikon_coolscan_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.9 can be exploited to trigger a NULL pointer dereference.
nvd
CVE-2014-8080P4MEDIUMCVSS 5.0v12.04v14.04+1 more2014-11-03
CVE-2014-8080 [MEDIUM] CVE-2014-8080: The REXML parser in Ruby 1.9.x before 1.9.3-p550, 2.0.x before 2.0.0-p594, and 2.1.x before 2.1.4 al The REXML parser in Ruby 1.9.x before 1.9.3-p550, 2.0.x before 2.0.0-p594, and 2.1.x before 2.1.4 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document, aka an XML Entity Expansion (XEE) attack.
nvd
CVE-2018-12398P4MEDIUMCVSS 6.5v14.04v16.04+2 more2019-02-28
CVE-2018-12398 [MEDIUM] CVE-2018-12398: By using the reflected URL in some special resource URIs, such as chrome:, it is possible to inject By using the reflected URL in some special resource URIs, such as chrome:, it is possible to inject stylesheets and bypass Content Security Policy (CSP). This vulnerability affects Firefox < 63.
nvd
CVE-2018-18494P4MEDIUMCVSS 6.5v14.04v16.04+2 more2019-02-28
CVE-2018-18494 [MEDIUM] CWE-346 CVE-2018-18494: A same-origin policy violation allowing the theft of cross-origin URL entries when using the Javascr A same-origin policy violation allowing the theft of cross-origin URL entries when using the Javascript location property to cause a redirection to another site using performance.getEntries(). This is a same-origin policy violation and could allow for data theft. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64.
nvd
CVE-2020-7064P4MEDIUMCVSS 5.4v12.04v14.04+4 more2020-04-01
CVE-2020-7064 [MEDIUM] CWE-125 CVE-2020-7064: In PHP versions 7.2.x below 7.2.9, 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while parsing EXIF data In PHP versions 7.2.x below 7.2.9, 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while parsing EXIF data with exif_read_data() function, it is possible for malicious data to cause PHP to read one byte of uninitialized memory. This could potentially lead to information disclosure or crash.
nvd
CVE-2018-5133P4MEDIUMCVSS 6.5v14.04v16.04+1 more2018-06-11
CVE-2018-5133 [MEDIUM] CWE-200 CVE-2018-5133: If the "app.support.baseURL" preference is changed by a malicious local program to contain HTML and If the "app.support.baseURL" preference is changed by a malicious local program to contain HTML and script content, this content is not sanitized. It will be executed if a user loads "chrome://browser/content/preferences/in-content/preferences.xul" directly in a tab and executes a search. This stored preference is also executed whenever an EME video pl
nvd
CVE-2020-25212P4HIGHCVSS 7.0v14.04v16.04+2 more2020-09-09
CVE-2020-25212 [HIGH] CWE-367 CVE-2020-25212: A TOCTOU mismatch in the NFS client code in the Linux kernel before 5.8.3 could be used by local att A TOCTOU mismatch in the NFS client code in the Linux kernel before 5.8.3 could be used by local attackers to corrupt memory or possibly have unspecified other impact because a size check is in fs/nfs/nfs4proc.c instead of fs/nfs/nfs4xdr.c, aka CID-b4487b935452.
nvd
CVE-2019-12387P4MEDIUMCVSS 6.1v14.04v16.04+2 more2019-06-10
CVE-2019-12387 [MEDIUM] CWE-74 CVE-2019-12387: In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an attacker to inject invalid characters such as CRLF.
nvd
CVE-2018-5132P4MEDIUMCVSS 6.5v14.04v16.04+1 more2018-06-11
CVE-2018-5132 [MEDIUM] CWE-200 CVE-2018-5132: The Find API for WebExtensions can search some privileged pages, such as "about:debugging", if these The Find API for WebExtensions can search some privileged pages, such as "about:debugging", if these pages are open in a tab. This could allow a malicious WebExtension to search for otherwise protected data if a user has it open. This vulnerability affects Firefox < 59.
nvd
CVE-2018-8885P4HIGHCVSS 7.0v14.04v16.04+1 more2018-03-28
CVE-2018-8885 [HIGH] CWE-362 CVE-2018-8885: screenresolution-mechanism in screen-resolution-extra 0.17.2 does not properly use the PolicyKit D-B screenresolution-mechanism in screen-resolution-extra 0.17.2 does not properly use the PolicyKit D-Bus API, which allows local users to bypass intended access restrictions by leveraging a race condition via a setuid or pkexec process that is mishandled in a PolicyKitService._check_permission call.
nvd
CVE-2018-18497P4MEDIUMCVSS 6.5v14.04v16.04+2 more2019-02-28
CVE-2018-18497 [MEDIUM] CVE-2018-18497: Limitations on the URIs allowed to WebExtensions by the browser.windows.create API can be bypassed w Limitations on the URIs allowed to WebExtensions by the browser.windows.create API can be bypassed when a pipe in the URL field is used within the extension to load multiple pages as a single argument. This could allow a malicious WebExtension to open privileged about: or file: locations. This vulnerability affects Firefox < 64.
nvd
CVE-2018-4146P4MEDIUMCVSS 6.5v16.04v17.102018-04-03
CVE-2018-4146 [MEDIUM] CWE-119 CVE-2018-4146: An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 i An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "WebKit" component. It allows attackers to cause a denial of service
nvd
CVE-2014-8150P4MEDIUMCVSS 4.3v10.04v12.04+2 more2015-01-15
CVE-2014-8150 [MEDIUM] CVE-2014-8150: CRLF injection vulnerability in libcurl 6.0 through 7.x before 7.40.0, when using an HTTP proxy, all CRLF injection vulnerability in libcurl 6.0 through 7.x before 7.40.0, when using an HTTP proxy, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in a URL.
nvd
Canonical Ubuntu Linux vulnerabilities | cvebase